{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4e5d33df-7684-52c1-ad38-e8a040587acf",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "aiohttp",
      "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
      "version": "3.8.1.post15+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-33124",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e0b810d0-ca51-56e4-b97c-2dac42736154",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post15+tuxcare."
      }
    },
    {
      "id": "CVE-2023-37276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1d33d81c-bca4-5b8f-be8b-8d3921de63b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-47627",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6ef6e040-13ca-5074-a92e-4694546263c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49081",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:eae610b7-278e-50c6-8f43-6e57e8789e7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49082",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ea18ad9d-66e4-57e5-bea6-b0cf5688fb03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23334",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e78523a0-77c3-50b1-a6ec-147e21832e89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23829",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:93c41038-e86f-5f4c-aa55-625bd3c15da9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-27306",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1218a0c4-eb0c-5b3f-8a9d-346420756712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-30251",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a810a137-1f88-5991-aa1e-ae690a6a197d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-52304",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0d5e77c7-6ecf-5db6-9b22-aa3f14a9cf73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-53643",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d90a2f50-385d-5187-9788-c075bad3fa9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69223",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e92bbff4-d03a-59e6-9e49-b68f61d15639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69223 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69224",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3681e7c7-e65a-5db8-818b-c61dc850804c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69225",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b431cf5c-20be-5f14-b8b8-8c98391e317c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69226",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1c2d0f0f-9f9e-51fe-af1e-60750a668b84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69227",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6c8dcfb2-c7f8-5fde-b940-de3abf3f46cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69228",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f403039d-d8ae-5e87-b33f-f6604d8c7ed2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69229",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c31b6607-2b52-5249-9ef0-f4ced083c2b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69230",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bf646690-9af3-560a-9600-a3e6b2118b88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-22815",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0ee73ae7-c38b-5dc4-bd59-b82501c9dac3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34513",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4347e290-b4bd-5eb5-8d74-79bd9d6795f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34514",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d4cd8143-18b6-509b-84bc-15d5ae5f0e3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34515",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9f04de13-0ad5-5ada-b9ad-d07a220bd695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34516",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e34d98cc-2eed-5b51-a793-7c84ffee90af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34517",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e46b952f-583b-5dca-a40f-770dc2eff4ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34518",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:63f3f574-6090-50b1-966d-556887c96bf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34519",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:aeca9fea-4cc5-5055-89f8-982e92107bbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34520",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ae55c536-02d6-5b2d-be8a-40ba8aea9d8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34525",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9c99ffff-ad40-5371-8d77-84c35b2055ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34993",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9d4b87ce-ee5b-5218-b82f-5bdb73dc578e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-47265",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:093c1b4b-6ff3-5196-bdae-7fe3552eca93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-50269",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2ab3e3b2-cd85-5898-9a8b-00d4f6208f6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54273",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:640d4431-c5dd-5676-b92f-fe6551ec0f61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54274",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6642a6b3-4b55-5f91-9c1b-1195a12ccd13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54275",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c2353d76-3d96-5760-b03d-1ac6aacd7dac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9149c103-5bf7-5902-90dd-9c846922037f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54277",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:586f4bb1-10cf-58d8-a138-d5cfab1ac3d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54278",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c1af586f-d8ad-587a-a224-8aa8cc3be480",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54279",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1a4be847-fb48-586f-b915-35b17a744f4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54280",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3b401bcb-2987-5f20-a60a-9c1385a114c2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post15+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59881",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1b6ba84a-04ca-5a71-87f4-de2551975a85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69243",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3d22b416-4f69-5900-9cb2-a82db3265ecd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69244",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:444f57fc-4026-52d2-8b23-0e7660e4c462",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-pjjw-qhg8-p2p9",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3a61b159-2d5e-5dfa-8bf0-2743e226033f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post15+tuxcare of aiohttp."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
    }
  ]
}